←back to thread

189 points udev4096 | 1 comments | | HN request time: 0.251s | source
Show context
hooli_gan[dead post] ◴[] No.42137400[source]
[flagged]
1. goku12 ◴[] No.42139169[source]
This is a digital security company reporting their findings, along with the fix. They did everything that could be expected of them. The real problem is how long RH took to address vulnerabilities. OSS isn't an excuse. There are other OSS projects with much less resources, that take security much more seriously. To make it worse, it isn't easy switch IdP software - even for OSS ones.